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Amendments to the Claims; 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

Claim 1 (currently amended): A method of managing access by a client to user-specific 
information maintained in connection with a plurality of services, the method comprising 
maintaining a plurality of items of user-specific information in more than one of a 
plurality of services offered by a web-services provider and used by a user of said 
plurality of services; 

obtaining a plurality of client access requests directed to accessing the plurality of 
items of user-specific information maintained in the more than one of the plurality of 
services, said plurality of access requests being translated from a task request that 
requires the client to access the plurality of items of user-specific information in order w> 

complete the task request; and 

for Mch of the pjjgajjtt of items o f ..ser-specific information required by the 

client to complete the task request: 

determining if the client has consent to access e»e^f the plurality of 
item[[s]] of user-specific information required by the client to complete the task 
request; 

selectively obtaining consent, from a party having authority to grant 
access to the client, for the client to access the u uo of the plura lit y n f item[[s]] of 
user-specific information if the client lacks consent as a function of said 
determining; and 

filling the ftoKty-ef client access requesttfs]] directed to the item if th* 
client has consent to access eaeh-ef the pteraKty-ef item[[s]] of user-specific 
information i n tho more t hi n i u uo of the plurality of aorvio es. 

Claim 2 (original): The method of claim 1 further comprising: 
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initiating the task request requiring the client to access the plurality of items of 
user-specific information in order to complete the task request; and 

translating the task request into the plurality of client access requests to complete 

the task request. 

Claim 3 (currently amended): The method of claim 2 wherein selectively obtaining 
consent for the client to access the u no of the plurali t y o f item[[s]] of user-specific 
information comprises: 

identifying the task request; 

placing the identified task request in a task queue; 

identifying the party with authority to grant consent to the client to access the ene 
of fro plurality ofitem[[s]] of user-specific information for which the client lacked 

consent to access; and 

displaying a consent menu to the identified party with authority, said consent 
menu prompting the identified party to grant or deny consent for the client to access the 
oiic Q fthoplurality-ofitem[[s]1 of user-specific information for which the client lacked 
consent to access. 

Claim 4 (previously presented): The method of claim 3 wherein the identified party with 
authority to grant consent is the user of the plurality of services offered by the web- 
services provider and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the user. 

Claim 5 (currently amended): The method of claim 3 wherein the identified party with 
authority to grant consent is an owner of the u no of the plurality of item[[s]] of user- 
specific information for which the client lacked consent to access and wherein displaying 
the consent menu to the identified party comprises displaying the consent menu to the 
owner. 
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Claim 6 (original): The method of claim 5 wherein the owner is the user of the 
plurality of services and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the user. 

Claim 7 (original): The method of claim 3 wherein the user of the plurality of services 
is a managed user and the identified party with authority to grant consent is a manager of 
the managed user and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the manager of the managed user. 

Claim 8 (currently amended): The method of claim 3 wherein displaying the consent 
menu to the identified party comprises: 

displaying an indication of the one of tho plurcdity of item[[s]] of user-specific 
information for which the client lacked consent to access; 

displaying an identity of the client; and 

displaying an intended use of the client of the u no of tho plurality of item[[s]l of 
user-specific information for which the client lacked consent to access. 

Claim 9 (original): The method of claim 8 wherein displaying a consent menu to the 
identified party further comprises displaying a method of access requested by the cliem to 
complete the initiated task request. 

Claim 10 (original): The method of claim 8 wherein displaying a consent menu to the 
identified party further comprises displaying an indication of a status of each of the 
plurality of client access requests translated from the task request. 

Claim 1 1 (original): The method of claim 1 0 wherein displaying an indication of the 
status of each of the plurality of client access requests comprises displaying an indicalion 
of whether the client has consent from the identified party to access the plurality of items 
of user-specific information in the more than one of the plurality of services. 
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Claim 12 (currently amended): The method of claim 3 wherein identifying the task 
request comprises: 

identifying the plurality of client access requests to complete the task request; and 
identifying the o^oftho plurality of item[[sj] of user-specific information for 
which the client lacked consent to access. 

Claim 13 (currently amended): The method of claim 3 further comprising: 

providing a consent acceptance message being indicative of whether the identified 

party granted consent for the client to access the ui w of the plurality of item[[s]] of user • 

specific information for which the client lacked consent; and 

updating an access control list associated with the one of Iho plurality nf item[[;;|] 

of user-specific information for which the client lacked consent if the consent acceptance 

message indicates that the identified party granted consent, whereby upon updating said 

access control list, the client has consent to access the o n e o f tho pku-ality nfitem[[s]] of 

user-specific information. 

Claim 14 (original): The method of claim 13 further comprising removing the identified 
task from the task queue if the consent acceptance message indicates that the identified 
party granted consent. 

Claim 15 (currently amended): The method of claim 13 further comprising transmitting a 
consent success message to the client, said consent success message being indicative of 
whether the identified party granted consent for the client to access the one-efthe 
ph*aHty-of item[[s]] of user-specific information for which the client lacked consent. 

Claim 16 (currently amended): The method of claim 13 wherein updating the access 
control list further comprises setting a time limit in which the client has consent to access 
the o»e of tho plurality of item[[s]] of user-specific information. 

Claim 17 (currently amended): The method of claim 3 wherein displaying the consent 
menu to the identified party further comprises displaying an invitation to allow the chent 
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te enjoy a one-time only access to the u n o o f the plurality of item[[s]] of user-specific 
information for which the client lacked consent. 

Claim 18 (currently amended): The method of claim 3 wherein selectively obtaining 
consent for the client to access the o a e of the plura li ty o f item[[s]] of user-specific 
information further comprises sending an alert message to the party with authority to 
grant consent, said alert message alerting the party with authority to grant consent that the 
client seeks access to the u uc of tho plurality of tom[M] of user-specific information for 
which the client lacked consent. 

Claim 19 (currently amended): The method of claim 3 fiirther comprising: 

providing a consent acceptance message being indicative of whether the identified 
party granted consent for the client to access the o ne o f tho plurality o f item[[s]] of user- 
specific information for which the client lacked consent; 

granting consent to allow the client to access the o u o of tho plural it y o f item[[s]) 
of user-specific information if the consent acceptance message indicates that the 
identified party granted consent. 

Claim 20 (currently amended): TJie method of claim 1 , wherein one One or more 
computer-readable media having have computer-executable instructions for performing 
the method recited in claim 1 . 

Claim 21 (currently amended): A task-based method of managing consent transactions in 
a network computing environment, said network computing environment including a 
web-services provider providing a first service and a second service, a user of the first 
service and the second service, and a client of the web-services provider, the method 
comprising: 

maintaining a first data store of user-specific information in connection with lite 
first service; 

maintaining a second data store of user-specific information in connection with 
the second service; 
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obtaining a first access request from the client and directed to the first service, 
said first access request indicating a first item of user-specific information maintained it) 
the first data store to which the client seeks access in order to complete a task request; 

obtaining a second access request from the client and directed to the second 
service, said second access request indicating a second item of user-specific information 
maintained in the second data store to which the client seeks access in order to complete 
the task request; 

determining if the client has consent to access the first item of user-specific 
information and sgparately determine if the client has consent to access the second item 

of user-specific information; 

selectively obtaining consent if consent does not currently exist to allow the client 
to access the first item of user-specific information as a function of said determining, 
wherein selectively obtaining consent includes: 

identifying a party with authority to grant consent to the client to access 
the first item of user-specific information; and 

displaying a consent menu to the identified party with authority, said 
consent menu prompting the identified party to grant or deny consent to the client 
to access the first item of user-specific information. 

Claim 22 (original): The method of claim 21 further comprising: 

initiating a task request from the user that requires the client to access the first 

item of user-specific information and the second item of user-specific information; and 
translating the task request into the first access request and the second access 

request. 

Claim 23 (previously presented): The method of claim 21 wherein selectively obtainiog 
consent further includes: 

identifying the task request; 

retrieving a task manifest corresponding to the task request, said task manifest 
identifying the first and second items of user-specific information; and 

preparing an entry for display on the consent menu based on the task manifest. 
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Claim 24 (original): The method of claim 21 further comprising filling the second 
i request only if the client has consent to access both the first item of user-specific 



access i 



information and the second item of user-specific information. 

Claim 25 (currently amended): The method of claim 21 , wherein oOne or more 
computer-readable media haveiag computer-executable instructions for performing the 
method recited in claim 21 . 

Claim 26 (currently amended): A method of managing consent transactions in a network 
computing environment, said network computing environment including a web-servic<«s 
provider providing a plurality of services, a user of the plurality of services, said web- 
services provider maintaining user-specific information associated with the user in 
connection with the plurality of services, and a client of the web-services provider, said 
user initiating a task request wilh the client, said client directing a plurality of access 
requests to the plurality of services in order to complete the task request, the method 
comprising: 

selectively obtaining consent if the client lacks consent required to complete one 
or mor e of the plurality of access requests, wherein, for each of the one or more of the 
plurality of access requests, said obtaining consent includes: 

identifying a party with authority to grant consent to allow the client to 

complete the oaa of flio plurality of access requests]] fox which tho client 

consent ; and 

initiating a consent request transaction with the identified party with 
authority to grant consent, said consent request transaction inviting the party with 
authority to grant consent to allow the client to complete the ono of tho plurali ty 
of access request[[s]]. 
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Claim 27 (currently amended): The method of claim 26 wherein initiating a consent 
request transaction further comprises displaying a consent menu to the identified party 
with authority to grant consent, said consent menu prompting the identified party to grant 
or deny consent for the client to complete the o ne o f to plurality nf access request^]] 

Claim 28 (original): The method of claim 27 wherein the identified party with authority 
to grant consent is the user of the plurality of services and wherein displaying the consent 
i to said identified party comprises displaying the consent menu to the user. 



menui 



Claim 29 (original): The method of claim 27 wherein the identified party with authority 
to grant consent is an owner of the user-specific information associated with the user and 
wherein displaying the consent menu to said identified party comprises displaying the 
consent menu to the owner 

Claim 30 (original): The method of claim 27 wherein the user of the plurality of 
services is a managed user and the identified party with authority to grant consent is a 
manager of the managed user and wherein displaying the consent menu to said identified 
party comprises displaying the consent menu to the manager of the managed user 

Claim 31 (currently amended): The method of claim 27 wherein prompting the identified 
party to grant or deny consent for the client to complete the o n e o f to p l urali t y of acc ess 
requests]] comprises providing a one-time only consent option whereby when said 
identified party selects the one-time only consent option the client is allowed to complete 
the qw of uio plurality nf access requests]] only for completing the task request. 

Claim 32 (original): The method of claim 26 wherein initiating the consent transaciion 
with the party with authority to grant consent further comprises sending an alert mes*»ge 
to said party with authority, said alert message alerting said party that the client is seeking 
access to the user-specific information. 
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Claim 33 (currently amended): The method of claim 26, wherein oQne or more 
computer-readable media haveiag computer-executable instructions for performing the 
method recited in claim 26. 

Claim 34 (currently amended): A system for controlling access to user-specific 
information in a network computing environment, the system comprising: 
a web-services provider providing a service; 

a user of the service, the web-services provider maintaining [[an]] ^ plurality of 
items of user-specific information associated with the user in a data store associated wiih 
the service; 

a client of the web-services provider, said client operatively communicating with 
the user and seeking access to ™e or more of the pjuraj^tyof items of user-specific 
information; 

an access control list associated with the pJuiality_of items of user-specific 
information, said access control Ust indicating for earh of the plurality of items, whether 
consent exists to allow the client to access the item of user-specific information; and 

a consent management system for controlling an update of the access control lirf, 
said consent management system initiatin g for each of thr one or more of the pluralit y of 
items, a consent transaction with a party having authority to grant consent to update the 
access control list when the access control list indicates that consent does not exist to 
allow the client to access the item of user-specific information. 

Claim 35 (original): The system of claim 34 wherein the consent management system 
comprises a consent user interface for displaying a consent menu to the party having 
authority to update the access control list, said consent menu prompting the identified 
party to grant or deny consent to allow the client to access the item of user-specific 
information, whereby if the identified party grants consent the consent management 
system operatively updates the access control list to indicate that the client has consent to 
access the item of user-specific information. 
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Claim 36 (original): The system of claim 35 wherein the consent management system 
further comprises a consent server associated with the consent user interface for 
determining the party having authority to update the access control list and for 
operatives updating the access control list if the identified party grants consent to allow 
the client to access the item of user-specific information. 

Claim 37 (original): The system of claim 35 wherein the consent menu identifies a 
plurality of menu entries comprising: 
an identity of the client; 

a method by which the client seeks to access the item of user-specific 
information; and 

a purpose for which the client seeks to access the item of user-specific 
information. 

Claim 38 (original): The system of claim 37 wherein the plurality of menu entries 
further comprises a value proposition associated with the purpose for which the chent 
desires to access the first item of user-specie information. f 

Claim 39 (currently amended): A system for controlling access to user-specific 
information in a network computing environment, said system comprising: 
a user transmitting a task request; 

a web-services provider providing a first service and a second service, said web- 
services provider maintaining a first of item of user-specific information associated with 
the user in connection with the first service and a second item of user-specific 
information associated with the user in connection with the second service, said first 
second services lately requiring consent before allowing access to the first and 
second items of user-specific information; 

a client in digital communication with the user and receiving the task request, said 
client translating the task request into a first access request and a second access request, 
said first access request being directed to the first service and seeking access to the f «* 
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hem of user-specific information and said second access request being directed to the 
second service and seeking accesa ,0 the second item of user-specific infomrauon; and 

a consent management sysrem being setectively invoked by the alien, ,f the Cent 
lacks consent to access the first item of user-specific infonnation, aaid conaent 
management system identifying a party with aotoority to gran, consent to the chent to 
access the firat item of user-specific infonnation and initiating a consent request 
transaction with fire pany with authority to grant consent to the client to access the firs, 
hem of user-specific information, aaid consent request transition inviting the party «,,!. 
authority to gran, consent to allow the client to access the firat item of user-apecfio 
infonnation. 

Claim 40 (original), The system of claim 39 whereto toe consent management system 
fether comprises a conaent user interface for displaying a consent menu to toe party v„«h 
authority to era., consent to the client to accesa the firs, item of user-apectfic 
information, 

Claim41 (original): The system of claim 40 wherein the consent menu identifies a 
plurality of menu entries comprising: 
an identity of the client; 

a method by which the client proposes to access the first item of user-specific 
information; and 

a purpose for which the client desires to access the first item of user-specific 
information. 

Claim 42 (original): The system of claim 41 wherein the plurality of menu entries 
further comprises a value proposition associated with the purpose for which the client 
desires to access the first item of user-specific information. 

Claim 43 (currently amended): A method of controlling access to user-specific 
information for use in connection with a network computing environment including a 
web-services provider, a user of a servic* provided by the web-services provider, and a 



- 12- 

PAGE 13/18 * RCVD AT 12/19/2005 2:43:08 PM [Eastern Standard Time] * SVR:USPTO-EFXRF-6/25 * DNIS:2738300 * CSID:3142314342 * DURATION (mm-ss):05-34 



DEC-1 9-2005 HON 01:50 PM SENNIGER POWERS FAX NO. 3142314342 P. 14/18 



BEST AVAILABLE COPY k™ o, 

client of the web-services provider, said web-services provider maintaining a data store 
of user-specific information associated with the user in connection with the service, and 

said client seeking access to on B «f a nluralitv of [[an]] items of user-specific 

information in the data store and transmitting an access request message directed to the 

service and indicating the * of the nluralitv of items of user-specific 

information in the data store to which the client seeks access, the method comprising^ 
each of tte one or mor* nf ihe plurality of items: 

comparing the access request message to an access control list associated with the 
service, said access control list identifying whether the client has permission to access the 
item of user-specific information; 

placing the access request in a pending request queue; 
transmitting a service response message to the client, said service response 
message indicating a fault if the access control list identifies that the client does not have 
permission to access the item of user-specific information and said service response 
message indicating a success if the access control list identifies that the client has 
permission to access the item of user-specific information; 

selectively obtaining consent, from a party having authority to grant consent to 
the client, for the client to access the item of user-specific information if the service 
response message received by the client indicates a fault; and 

filling the access request if the access control list authorizes the client to access 
the item of user-specific information in the data store and removing the access request 
from the pending request queue. 

Claim 44 (previously presented): The method of claim 43 wherein selectively obtainuig 

consent further includes: 

identifying a party with authority to grant permission to the client to access the 

item of user-specific information; and 

displaying a consent menu to the identified party with authority to grant 
permission, said consent menu prompting the identified party to grant or deny permis don 
for the client to access the item of user-specific information. 
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Claim 45 (original): The method of claim 44 wherein the identified party is the user of 
the service and wherein displaying a consent menu to the identified party compnses 
displaying the consent menu to the user. 

Claim 46 (original): The method of claim 44 wherein the identified party is an owner of 
the item of user-specific information and wherein displaying the consent menu to the 
identified party comprises displaying the consent menu to the owner. 

Claim 47 (original): The method of claim 44 wherein the user is a managed user and 
the identified party is a manager of the managed user and wherein displaying the consent 
menu to the identified party comprises displaying the consent menu to the manager of the 
managed user- 

Claim 48 (currently amended): TV method of clajm 43, wheginoOne or more 
computer-readable media having computer-executable instructions for performmg the 
method recited in claim 43. 
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